Skip to content

Security: red-hat-data-services/models-as-a-service

SECURITY.md

Security Policy

The Models as a Service (MaaS) project takes security seriously. We appreciate your efforts to responsibly disclose any security vulnerabilities you find.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

If you discover a security vulnerability in this project, please report it to the Red Hat Product Security team:

Please include as much of the following information as possible to help us triage your report:

  • Type of vulnerability (e.g., buffer overflow, SQL injection, cross-site scripting)
  • Full paths of related source files
  • Location of the affected source code (tag/branch/commit or direct URL)
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

The Red Hat Product Security team will acknowledge your report and work with you to understand and address the issue. You will receive a response within 5 business days.

Supported Versions

Security updates are applied to the latest release. We recommend always running the most recent version.

Disclosure Policy

We follow Red Hat's vulnerability disclosure policy. Once a fix is available, we will coordinate the release and disclosure timeline.

There aren't any published security advisories